vuupcsetup_full.exe

VuuPC

ClickMeIn Ltd.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application vuupcsetup_full.exe by ClickMeIn has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the installCore installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from 113.171.224.216 and multiple other hosts.
Publisher:
VuuPC Limited  (signed by ClickMeIn Ltd.)

Product:
VuuPC

Description:
VuuPC Setup

Version:
1.0.0.267

MD5:
161d08470f5cb732cab3d5d3435cd941

SHA-1:
b719b02d225b4ba81cf595502e14333a72148ca7

SHA-256:
cbb02afab08d82582869d37e799e8964d63e27b07999b6baceb1ee85ce7e06eb

Scanner detections:
11 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/8/2024 9:43:57 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Clickmein
2015.0.3436

Baidu Antivirus
Adware.Win32.VuuPc
4.0.3.14622

Dr.Web
Adware.Downware.2258
9.0.1.0173

ESET NOD32
Win32/VuuPc
8.9972

K7 AntiVirus
Unwanted-Program
13.180.12463

McAfee
Artemis!161D08470F5C
5600.7092

Norman
Downloader
11.20140622

Reason Heuristics
PUP.Installer.ClickMeIn.P
14.6.22.9

Sophos
AnyProtect
4.98

Trend Micro House Call
TROJ_GEN.F47V0602
7.2.173

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
7.4 MB (7,724,216 bytes)

Product version:
1.0.0.267

Copyright:
Copyright 2013

Trademarks:
VuuPC is a trademark of CMI Limited

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\vuupcsetup_full.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
3/17/2014 7:50:06 PM

Valid to:
3/17/2015 7:50:06 PM

Subject:
CN=ClickMeIn Ltd., O=ClickMeIn Ltd., L=Nicosia, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B3329DE736323

File PE Metadata
Compilation timestamp:
12/6/2009 4:20:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:poW0Q0+eFT8Cy1/XtnFtZXaxRVA2PQQ2E:poWx0+cTUxiLAVBE

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9944

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file vuupcsetup_full.exe has been seen being distributed by the following 3 URLs.

http://113.171.224.216/.../VuuPCSetup.exe

http://113.171.224.246/.../VuuPCSetup.exe

Remove vuupcsetup_full.exe - Powered by Reason Core Security